Application of Act
Subject to the provisions of this Act, it applies to the processing of digital personal data within the territory of India where the personal data is collected in digital form, or in non-digital form and subsequently digitised.
It also applies to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India.
Nothing in this Act shall apply to personal data that is processed by an individual for any personal or domestic purpose, and personal data that is made or caused to be made publicly available by the Data Principal or any other person who is under an obligation to make such personal data publicly available.
- This is the extraterritorial hook: a foreign company with no Indian office can still fall under DPDP if it profiles, sells to, or otherwise offers goods/services to people located in India.
- Purely offline, non-digitised personal data (e.g. a paper register never scanned) sits outside scope — but the moment it's digitised, it's in.
- Data an individual chooses to make public themselves (e.g. a public social media profile) is carved out, as is purely personal/household use.
Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.